Plain-English explanations of the technical terms and legislation used in this document.
- AES-256
- A strong, widely used method of scrambling stored data so that only authorised people can read it.
- Artificial-intelligence-assisted triage
- Using computer software that mimics human judgement to help sort or prioritise patients before a clinician sees them.
- Audit log
- An automatic record of who accessed or changed information and when, used to detect and investigate misuse.
- Bring-your-own-device (BYOD)
- An arrangement that lets staff use their own personal phones, tablets or computers for work.
- Business continuity plan
- A plan setting out how a service will keep running, or quickly recover, when something disrupts it.
- Caldicott Guardian
- The senior person responsible for protecting the confidentiality of people's health and care information.
- Caldicott Principles
- A set of nationally agreed rules for handling confidential patient information safely and appropriately.
- Care Quality Commission (CQC)
- The independent regulator of health and social care services in England.
- Cloud-hosted
- Software and data run on remote internet servers managed by a provider, rather than on computers in your own building.
- Common law duty of confidentiality
- A long-standing legal duty to keep information that someone shares in confidence private unless there is a proper reason to disclose it.
- Computer Misuse Act 1990
- The law that makes it a criminal offence to access or damage computer systems without permission.
- Conditional access
- A security rule that only allows a sign-in if certain conditions are met, such as the device being approved and up to date.
- Controlled drug
- A medicine whose supply, storage and records are tightly restricted by law because of its potential for misuse.
- Cookies
- Small files a website stores on a visitor's device to remember them or track how the site is used.
- CREST-accredited
- Carried out by a security tester certified by CREST, an internationally recognised body for the cybersecurity testing industry.
- Cyber Assessment Framework (CAF)
- A national framework for checking how well an organisation manages cyber risks to important services.
- Cyber Essentials Plus
- A government-backed certification, with independent testing, showing an organisation has basic cybersecurity protections in place.
- Data (Use and Access) Act 2025
- A United Kingdom law that updates the rules on using and sharing data, including health and care information.
- Data Protection Act 2018
- The United Kingdom law that sits alongside the UK GDPR and governs how personal information must be handled.
- Data Protection Impact Assessment (DPIA)
- A check done before a new activity to identify and reduce risks to people's personal data.
- Data Protection Officer (DPO)
- The person responsible for advising an organisation on data-protection law and monitoring that it is followed.
- Data processing agreement
- A written contract that sets out how a supplier handling personal data on your behalf must protect it.
- Data residency
- The physical country or region where an organisation's data is stored.
- Data Security and Protection Toolkit (DSPT)
- An online self-assessment that health and care organisations use to show they handle data and cybersecurity safely.
- Data subject
- The living individual that a piece of personal information is about.
- Denial of service (DoS / DDoS)
- An attack that floods a website or system with traffic so that genuine users cannot use it.
- DKIM
- An email security check that adds a digital signature so the recipient can confirm a message genuinely came from your organisation.
- DMARC
- An email security policy that tells receiving servers what to do with messages that fail anti-spoofing checks, helping to stop fraud.
- Electronic patient record (EPR)
- A patient's medical record held in a computer system rather than on paper.
- Electronic Prescription Service (EPS)
- A national service that sends prescriptions electronically from the prescriber to a pharmacy.
- Encryption
- Scrambling information so that only someone with the correct key can read it.
- Endpoint detection and response (EDR)
- Security software on computers and devices that spots, investigates and helps stop attacks.
- End-to-end encryption
- Protection that scrambles a message or call so that only the people communicating can read or hear it, and no one in between.
- European Economic Area (EEA)
- The European Union countries plus Iceland, Liechtenstein and Norway, treated as a single area for data-protection purposes.
- Fundamental standards
- The minimum standards of safety and quality below which care must never fall.
- GP Connect
- A national service that lets authorised health and care systems securely view and share information held in general-practice records.
- Health and Social Care Act 2008 (Regulated Activities) Regulations 2014
- The regulations setting out the fundamental standards that providers of regulated care must meet.
- HTTPS / HSTS
- HTTPS encrypts the connection between a browser and a website; HSTS (HTTP Strict Transport Security) forces that secure connection to always be used.
- Immutable backup
- A backup copy that cannot be altered or deleted for a set period, so it survives a ransomware attack.
- Information governance
- The framework for handling people's personal and health information legally, securely and appropriately.
- Information Commissioner's Office (ICO)
- The United Kingdom regulator responsible for upholding data-protection and information rights.
- ISO 27001
- An internationally recognised standard for managing information security within an organisation.
- Joiners-movers-leavers (JML)
- The process for granting, changing and removing someone's system access as they join, change role in, or leave an organisation.
- Least privilege
- Giving each person only the access they actually need to do their job, and no more.
- Mobile device management (MDM)
- Software that lets an organisation secure, control and, if needed, remotely wipe the phones, tablets and laptops used for work.
- Multi-factor authentication (MFA)
- Signing in with more than one proof of identity, such as a password plus a code or fingerprint, for stronger security.
- National Cyber Security Centre (NCSC)
- The United Kingdom's national authority providing advice and support on cybersecurity.
- Near miss
- An event that could have caused harm but did not, by chance or because it was caught in time.
- Network and Information Systems Regulations 2018 (NIS Regulations)
- The law setting cybersecurity and incident-reporting duties for operators of essential services and certain digital service providers.
- Nominated Individual
- The senior person responsible to the regulator for supervising how a service is provided.
- Passkey / FIDO2
- A modern, password-free way of signing in that is highly resistant to phishing, using a security key or a device's built-in security.
- Patch management
- Keeping software and systems updated with the fixes that close security weaknesses.
- Penetration testing
- Authorised, simulated hacking of a system to find security weaknesses before real attackers do.
- Personal Demographics Service
- A national electronic database of patient contact and demographic details used across health and care services.
- Phishing
- Fraudulent emails or messages designed to trick people into revealing passwords or other sensitive information.
- Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR)
- The law covering electronic marketing, cookies and the privacy of electronic communications.
- Ransomware
- Malicious software that locks or encrypts an organisation's data and demands payment to release it.
- Record of Processing Activities (ROPA)
- A documented inventory of the personal data an organisation holds and how and why it is used.
- Recovery-point objective (RPO)
- The maximum amount of data, measured in time, that an organisation can afford to lose in an outage.
- Recovery-time objective (RTO)
- The maximum acceptable length of time a system can be down before it must be restored.
- Regulated activity
- A type of care or treatment the law requires a provider to register with the regulator to deliver.
- Registered Manager
- The person registered with the regulator as responsible for the day-to-day running of a service.
- Residual risk
- The level of risk that remains after existing controls and safeguards have been taken into account.
- Risk assessment
- A structured check identifying what could cause harm and what is being done to prevent it.
- Role-based access control
- Granting access to systems according to a person's job role, so they only see what that role requires.
- Safeguarding
- Protecting people's health, wellbeing and rights and keeping them safe from abuse, harm or neglect.
- Senior Information Risk Owner (SIRO)
- The senior person accountable for managing information risk across an organisation.
- Service-level agreement (SLA)
- A contract setting out the standard of service, such as availability or response time, that a supplier must provide.
- Single assessment framework
- The structure the regulator uses to judge a service, built around quality statements and five key questions (safe, effective, caring, responsive, well-led).
- Smartcard
- A secure plastic card with a chip used, with a passcode, to prove identity and access clinical systems such as electronic prescribing.
- Social engineering
- Manipulating people through deception into giving away information or access they should not.
- Special category data
- Particularly sensitive personal data, such as information about a person's health, that the law gives extra protection.
- SPF
- An email security check that lists which servers are allowed to send email for your organisation, helping to block forged messages.
- Spine
- The central national computer system that securely connects health and care services and their patient information.
- SQL injection
- An attack that inserts malicious database commands through a website to steal or damage data.
- Standard operating procedure (SOP)
- A written step-by-step instruction for carrying out a routine task consistently and safely.
- Sub-processor
- A further supplier that a data processor uses to help handle personal data on an organisation's behalf.
- TLS (Transport Layer Security)
- A standard that encrypts information as it travels across the internet to keep it private and unaltered.
- UK General Data Protection Regulation (UK GDPR)
- The United Kingdom's main data-protection law governing how personal information is collected and used.
- Virtual private network (VPN)
- A secure, encrypted connection over the internet that protects data travelling between a user and a network.
- Vulnerability scanning
- Automated checking of systems for known security weaknesses so they can be fixed.
- Web application firewall (WAF)
- A protective filter that screens incoming web traffic and blocks common attacks against a website or application.
- Zero-trust access
- A security approach that verifies every user and device on each request rather than trusting anything by default.